
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-11363 is an unauthenticated media file upload vulnerability in the Royal Addons for Elementor (Royal Elementor Addons and Templates) WordPress plugin. The flaw affects all versions before 1.7.1037 and stems from missing authorization checks on the wpr_addons_upload_file AJAX action, allowing any unauthenticated user to upload files to the server. It was discovered by researcher Envel Le Clainche, publicly disclosed on November 24, 2025, and assigned a CVE on December 15, 2025. The CVSS v3.1 base score is 5.3 (Medium), assessed by CISA-ADP (WPScan, Red Hat CVE).
The root cause is improper authorization (CWE-434: Unrestricted Upload of File with Dangerous Type) on the wpr_addons_upload_file WordPress AJAX action handler. An unauthenticated attacker can obtain a nonce value exposed via the WprConfig JavaScript object (accessible after a Template Kit import) and use it to POST arbitrary files to wp-admin/admin-ajax.php. Uploaded files are stored in /wp-content/uploads/wpr-addons/forms, a publicly accessible directory. The PoC published by WPScan demonstrates exploitation using a simple curl command with a crafted multipart form request (WPScan).
Successful exploitation allows unauthenticated attackers to upload arbitrary media files to a publicly accessible directory on the WordPress server. While the CVSS score reflects a low integrity impact with no direct confidentiality or availability impact, the ability to upload files to a web-accessible path could be chained with other vulnerabilities (e.g., insufficient file type validation) to achieve remote code execution, web shell deployment, or serve malicious content to site visitors. The scope is limited to WordPress sites running the affected plugin versions (WPScan, Red Hat CVE).
A public proof-of-concept is available via WPScan, demonstrating exploitation with a single curl command requiring only a nonce obtainable from the frontend JavaScript object WprConfig. The EPSS score is 0.023% (very low), and the vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution or confirmed in-the-wild exploitation has been reported as of the available data (WPScan, Red Hat CVE).
/wp-content/plugins/royal-elementor-addons/ for version indicators.WprConfig to retrieve the nonce value from the exposed JavaScript configuration object.evil.jpg or a file with a disguised extension) and construct a POST request targeting the AJAX endpoint:curl -X POST http://example.com/wp-admin/admin-ajax.php \
-F "action=wpr_addons_upload_file" \
-F "triggering_event=click" \
-F "wpr_addons_nonce=<NONCE>" \
-F "uploaded_file=@evil.jpg"/wp-content/uploads/wpr-addons/forms/ and is publicly accessible via the web server, enabling further exploitation such as serving malicious content or chaining with a file inclusion vulnerability (WPScan)./wp-admin/admin-ajax.php with action=wpr_addons_upload_file from unauthenticated (non-logged-in) sources; multipart form-data uploads from unknown or suspicious IP addresses./wp-content/uploads/wpr-addons/forms/, particularly files with double extensions (e.g., .php.jpg), web shells, or files with unusual names not matching legitimate form submissions.admin-ajax.php with action=wpr_addons_upload_file from IPs with no prior site interaction; HTTP 200 responses to such requests from unauthenticated sessions./wp-content/uploads/wpr-addons/forms/ directory (WPScan).Update the Royal Elementor Addons and Templates plugin to version 1.7.1037 or later, which includes proper authorization checks on the wpr_addons_upload_file action. As a temporary workaround, administrators can use a Web Application Firewall (WAF) rule to block POST requests to admin-ajax.php with action=wpr_addons_upload_file from unauthenticated users, or restrict access to the /wp-content/uploads/wpr-addons/forms/ directory via server configuration. Monitoring the uploads directory for unexpected file types is also recommended (WPScan).
The vulnerability was covered in Sucuri's December 2025 vulnerability patch roundup and noted in the Wordfence Intelligence weekly WordPress vulnerability report. The security community has flagged it on platforms including Bluesky and CIRCL's vulnerability lookup service. Overall community reaction is moderate given the medium CVSS score, though the unauthenticated nature of the exploit has drawn attention from WordPress security researchers (Sucuri Blog, Wordfence Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."